CVE-2018-17457: Google Chrome

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

An object lifecycle issue in Blink could lead to a use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Affected products

  • Google Chrome: before 69.0.3497.81 (fixed in 69.0.3497.81)

Published 2019-01-09. Last modified 2026-06-17.